CVE-2022-1221
Gwyn's Imagemap Selector <= 0.3.3 - Reflected Cross-Site Scripting
Record summary
CVE-2022-1221 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 8, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Gwyn's Imagemap Selector | CVE List | 0.3.3 to ≤ 0.3.3 | affected |
gwyn\'s_imagemap_selectorBrowse gwyn\'s_imagemap_selector_project / gwyn\'s_imagemap_selector | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Gwyn's Imagemap Selector <=0.3.3 - Cross-Site ScriptingCVSS 6.1
Wordpress Gwyn's Imagemap Selector plugin 0.3.3 and prior contains a reflected cross-site scripting vulnerability. It does not sanitize the id and class parameters before returning them back in attributes.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the victim's browser, potentially leading to session hijacking, defacement, or theft of sensitive information.
Remediation
Update to the latest version of the WordPress Gwyn's Imagemap Selector plugin (0.3.3) or apply the vendor-supplied patch to fix the vulnerability.
Source: ProjectDiscovery